보안뉴스 아카이브
긴급도 100/100 심각도 9.8 · 치명적 악용확률 99.3% CISA KEV · 2024-11-25 랜섬웨어 악용 CWE-287

CVE-2023-28461

CISA 기관 조치 기한: 2024-12-16

Array Networks AG/vxAG ArrayOS

Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
KEV 필수 조치: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

벡터: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

NVD 상세 ↗   GitHub Advisory ↗   참고 링크 ↗

← 취약점 목록